Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-24486

42
FAUCET Score

CVE-2026-24486 is a high-severity Path Traversal vulnerability in Python-Multipart versions prior to 0.0.22, affecting products like fastapiexpert. It allows an unauthenticated attacker to write uploaded files to arbitrary filesystem locations by exploiting specific non-default configuration options (UPLOAD_DIR and UPLOAD_KEEP_FILENAME=True). While the CVSS score is 7.5 (HIGH), there is currently no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.0.22CPE matchmatch criteria
cpe:2.3:a:fastapiexpert:python-multipart:*:*:*:*:*:python:*:*

CVSS Data

CVSS version used by this source: 3.1

8.6HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.23%
Probability of exploitation in next 30 days
EPSS Percentile
80.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-52543 · Apr 30, 2026
This CVE's current EPSS score of 0.0223 is in the 66th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (32)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: python-multipartFixed in: 0.0.22
redhatpatch availablevia redhat_api
Product: Red Hat Satellite 6.18Fixed in: satellite/foreman-mcp-server-rhel9:sha256:ff4edaa605127e763ada037ec63ab7cc2054b853f079e7e28a0355234b24b2a0
View patch
redhatno patchvia redhat_api
Product: OpenShift LightspeedFixed in: openshift-lightspeed/lightspeed-service-api-rhel9
redhatno patchvia redhat_api
Product: Red Hat AI Inference ServerFixed in: rhaiis-preview/vllm-cuda-rhel9
redhatno patchvia redhat_api
Product: Red Hat AI Inference ServerFixed in: rhaiis/vllm-cuda-rhel9
redhatno patchvia redhat_api
Product: Red Hat AI Inference ServerFixed in: rhaiis/vllm-rocm-rhel9
redhatno patchvia redhat_api
Product: Red Hat AI Inference ServerFixed in: rhaiis/vllm-spyre-rhel9
redhatno patchvia redhat_api
Product: Red Hat AI Inference ServerFixed in: rhaiis/vllm-tpu-rhel9
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-25/lightspeed-chatbot-rhel8
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-26/lightspeed-chatbot-rhel9
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-26/mcp-tools-rhel9
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI) 3Fixed in: rhelai3/bootc-aws-cuda-rhel9
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI) 3Fixed in: rhelai3/bootc-azure-cuda-rhel9
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI) 3Fixed in: rhelai3/bootc-cuda-rhel9
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI) 3Fixed in: rhelai3/bootc-gcp-cuda-rhel9
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI) 3Fixed in: rhelai3/disk-image-cuda-rhel9
redhatno patchvia redhat_api
Product: Lightspeed CoreFixed in: lightspeed-core/lightspeed-stack-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-caikit-tgis-serving-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-feature-server-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-kserve-storage-initializer-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-llama-stack-core-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-trustyai-ragas-lls-provider-dsp-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-vllm-cpu-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-vllm-cuda-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-vllm-gaudi-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-vllm-rocm-rhel9
redhatno patchvia redhat_api
Product: Red Hat Satellite 6Fixed in: satellite/iop-advisor-engine-rhel9
redhatno patchvia redhat_api
Product: Red Hat Satellite 6Fixed in: satellite/iop-host-inventory-rhel9
redhatno patchvia redhat_api
Product: Red Hat Satellite 6Fixed in: satellite/iop-vmaas-rhel9
redhatno patchvia redhat_api
Product: Red Hat Satellite 6Fixed in: satellite/iop-vulnerability-engine-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-caikit-nlp-rhel9

Vendor Advisories (2)

redhatCVE-2026-24486Important

python-multipart: Python-Multipart: Arbitrary file write via path traversal vulnerability

Jan 27, 2026
pipGHSA-wp53-j4wj-2cfghigh

Python-Multipart has Arbitrary File Write via Non-Default Configuration

Jan 26, 2026

References

access.redhat.com / errata/RHSA-2026:10184
access.redhat.com / errata/RHSA-2026:1504
access.redhat.com / errata/RHSA-2026:19712
access.redhat.com / errata/RHSA-2026:3461
access.redhat.com / errata/RHSA-2026:3462
access.redhat.com / errata/RHSA-2026:3713
access.redhat.com / errata/RHSA-2026:3782
access.redhat.com / errata/RHSA-2026:3960
access.redhat.com / errata/RHSA-2026:42644
access.redhat.com / errata/RHSA-2026:44696
access.redhat.com / security/cve/CVE-2026-24486
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-24486.json
github.com / Kludex/python-multipart/commit/9433f4bbc9652bdde82bbe380984e32f8cfc89c4
Patch
github.com / Kludex/python-multipart/releases/tag/0.0.22
ProductRelease Notes
github.com / Kludex/python-multipart/security/advisories/GHSA-wp53-j4wj-2cfg
ExploitVendor Advisory